fix(runtime): gate node:sqlite on a NUL round-trip capability probe (#143312)

* fix(runtime): gate node:sqlite on a NUL round-trip capability probe

Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465 #140672.

* fix(runtime): expose capability diagnostics through doctor

Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.

* fix(update): preserve target Node version requirements

* fix(install): remove unused Node major probe state
This commit is contained in:
Peter Steinberger 2026-09-09 13:32:29 -07:00 • committed by GitHub
parent 227e2f4fe1
commit bf6f74b280
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
52 changed files with 1603 additions and 389 deletions

View file

@ -4,7 +4,7 @@ import { existsSync } from "node:fs";
import path from "node:path";
import { createInterface } from "node:readline";
import { fileURLToPath } from "node:url";
import { isSupportedOpenClawNodeVersion } from "./node-version.mjs";
import { nodeRuntimeFailure, SQLITE_CAPABILITY_PROBE } from "./node-sqlite.mjs";
function isUsableNode(nodePath) {
if (!existsSync(nodePath)) {
@ -13,13 +13,17 @@ function isUsableNode(nodePath) {
const result = spawnSync(
nodePath,
[
"--input-type=module",
"-e",
'import "node:sqlite"; process.stdout.write(process.versions.node);',
`const probe = ${SQLITE_CAPABILITY_PROBE}; process.stdout.write(JSON.stringify({ version: process.versions.node, probe }));`,
],
{ encoding: "utf8", timeout: 10_000, windowsHide: true },
);
return result.status === 0 && isSupportedOpenClawNodeVersion(result.stdout?.trim());
try {
const details = JSON.parse(result.stdout);
return result.status === 0 && !nodeRuntimeFailure(details.version, details.probe);
} catch {
return false;
}
}
function canInstallPrivateNode() {